Healthcare

Industry

Ryuk Ransomware Attack Reported Cost Universal Health Services (UHS) an Estimated $67 Million

September 1, 2020

Universal Health Services (UHS), one of the largest healthcare services provider shut down systems at healthcare facilities around the U.S. after a cyberattack hit its networks. UHS managed to restore most affected systems and hospital operations systems during late-October. UHS said that the Ryuk ransomware attack had an estimated impact of $67 million. In October 2020, the U.S. government warned of Ryuk ransomware attacks against healthcare industry organizations including hospitals and healthcare providers.

read more

$10 Million Ransom Demand Disables French Hospital – Patients Send Elsewhere.

August 29, 2022

The Center Hospitalier Sud Francilien (CHSF), a 1000-bed hospital located 28km from the center of Paris, suffered a cyberattack on Sunday, which has resulted in the medical center referring patients to other establishments and postponing appointments for surgeries. CHSF serves an area of 600,000 inhabitants, so any disruption in its operations can endanger the health, and even lives, of people in a medical emergency. “This attack on the computer network makes the hospital’s business software, the storage systems (in particular medical imaging), and the information system relating to patient admissions inaccessible for the time being,” explains CHSF’s announcement (translated).

French cybersecurity journalist Valéry Riess-Marchive identified signs of a LockBit 3.0 infection. If LockBit 3.0 is responsible for the attack on CHSF, it will violate the RaaS program’s rules, which prohibit affiliates from encrypting systems of healthcare providers.

read more

26 Healthcare Organizations Impacted by Cyberattack on NY Medical Billing Company.

April 12, 2022

New York billing company Practice Resources, LLC (PRL) disclosed a ransomware attack that impacted 942,000 individuals and 26 healthcare organizations. PRL began notifying 942,138 individuals of a ransomware attack that impacted 26 of its healthcare organization clients.

According to a notice posted on the California Attorney General’s Office website, PRL suffered a ransomware attack on April 12, 2022. PRL immediately took steps to secure its systems and gained assistance from third-party experts.The information involved in the attack potentially included names, addresses, health plan numbers, dates of treatment, and medical record numbers.

read more

Cyberattack on South Denver Cardiology Associates (SDCA) Affects 287,000 Patients

January 4, 2022

South Denver Cardiology Associates (SDCA) announced it was the victim of a cyberattack in January 2022. Files containing protected healthcare information of thousands of thousands of heart patients were accessed and potentially stolen by hackers. Unusual network activity was detected on January 4, 2022, and the SDCA breach response process was immediately initiated. Systems were isolated from the network and shut down. The breach has been reported to the HHS’ Office for Civil Rights as affecting up to 287,652 individuals.

read more

NHS 111 Emergency Line Hit by Cyberattack

August 4, 2022

A cyberattack at UK company Advanced causing a software outage affected NHS 111 digital services. The attack targeted Adastra clinical patient management software. Adastra is used to refer patients for care, including ambulances being dispatched, out-of-hours appointment bookings and emergency prescriptions. Advanced has indicated the issue might not be fully resolved until next week. According to NHS England, 111 services are still available. However, the Welsh Ambulance Service has warned that 111 calls may take longer to answer. In addition, NHS England warned that GPs could see an increase in the number of patients.

read more

Cyberattack at MCG Health Affected over 1.1M Patient Records, Lawsuits Filed.

March 25, 2022

More than 10 U.S. health care systems were breached during a cyberattack of Seattle-based MCG Health, affecting up to 1.1 million patients, HIPAA Journal reports. MCG Health, a subsidiary of Hearst Health, is facing multiple class-action lawsuits as a result of the breach, during which an “unauthorized third party” obtained patient files that included names, Social Security numbers, medical codes, mailing addresses, telephone numbers and email addresses. The lawsuits allege MCG Health acted negligently by failing to recognize the breach for at least two weeks – while one lawsuit alleges hackers gained access to data 2 years before the hack was discovered.

read more

2021 Benson Health Breach Affected 29,000 Patients.

May 5, 2021

North Carolina-based Benson Health began notifying 28,913 individuals of a healthcare data breach. On May 5, 2021, Benson Health discovered that an unauthorized party had attempted to gain access to Benson Health’s computer network. Further investigation revealed that the unauthorized party potentially accessed a dataset containing names, birth dates, Social Security numbers, and health and treatment information.

Benson Health’s investigation concluded on July 7, 2022, more than a year after the initial incident. Benson Health is providing individuals affected by the incident with free single-bureau credit monitoring services. HIPAA requires covered entities to notify impacted individuals of a healthcare data breach within 60 days of discovery.

read more

Over 38 Vision Practices Report Data Breaches Involving Eye Care Leaders EHR Incident

December 21, 2021

Eye Care Leaders, which offers an ophthalmology-specific EMR solution, experienced unauthorized access to its myCare Integrity system in December 2021. Since ECL began notifying impacted organizations of the breach, organizations have been steadily contributing reports to HHS’ Office for Civil Rights (OCR) data breach portal. The hack compromised data of millions of patients.

The types of information that have been exposed included patient names, dates of birth, medical record numbers, health insurance information, Social Security numbers, and information regarding the care received at the affected eye care practices. The breach was confined to the myCare Identity solution.

read more

Theft of Member Data Reported in ADA Ransomware Attack

April 22, 2022

ADA suffered a cyberattack that forced them to take affected systems offline. Online services were inaccessible, including the ADA Store, the ADA Catalog, MyADA, Meeting Registration, Dues pages, ADA CE Online, the ADA Credentialing Service, and the ADA Practice Transitions. As a result the cyberattack also affected state dental associations who rely on ADA’s online services to register an account or pay dues, such as those in New York, Virginia, and Florida,

Black Basta has claimed responsibility for the attack, and soon after begun leaking approximately 2.8 GB of data, including W2 forms, NDAs, accounting spreadsheets, and information on ADA members, which the threat actors claimed to be 30% of the data stolen in the attack.

read more

Baton Rouge General Hit by Cyberattack

June 28, 2022

General Medical Center had to switch to paper record-keeping after a cyberattack brought its EHR system offline June 28, WAFB reported. “First, and most importantly, the attack has not changed our ability to care for patients,” the hospital said in a statement to the TV station posted June 29. “We are continuing to provide patient care at all locations.” The medical center added that it is working with state and federal authorities and its security vendors to ensure patient data remains private. Baton Rouge General didn’t respond to requests from Becker’s for updates.

read more